CVE-2024-8261
Published: 03 March 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2024-8261 is an Authorization Bypass Through User-Controlled Key vulnerability (CWE-639) in Proliz Software OBS. It allows exploitation of incorrectly configured access control security levels. The issue affects OBS versions before 24.0927. The vulnerability has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating high severity primarily due to confidentiality impact.
A remote, unauthenticated attacker can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation enables the attacker to bypass authorization controls using a user-controlled key, potentially gaining unauthorized access to sensitive data within the affected OBS instance.
The USOM advisory at https://www.usom.gov.tr/bildirim/tr-25-0049 provides details on this vulnerability. Mitigation involves upgrading to OBS version 24.0927 or later, where the issue is addressed.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Authorization bypass in public-facing OBS application directly enables T1190 for remote unauthenticated initial access and data exposure.